PT-2024-9642 · Dell · Dell Data Lakehouse+5
Published
2024-03-06
·
Updated
2026-01-22
·
CVE-2024-37144
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00
Dell PowerFlex rack versions prior to RCM 3.8.1.0 and prior to RCM 3.7.6.0
Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0
Dell InsightIQ versions prior to 5.1.1
Dell Data Lakehouse versions prior to 1.2.0.0
Description
The issue is related to insecure storage of sensitive information. A high privileged attacker with local access could potentially exploit this, leading to information disclosure. The attacker may use disclosed information to gain unauthorized access to pods within the cluster.
Recommendations
For Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, update to a version that includes the fix for this issue.
For Dell PowerFlex rack versions prior to RCM 3.8.1.0 and prior to RCM 3.7.6.0, update to a version that includes the fix for this issue.
For Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, update to version 4.6.1.0 or later.
For Dell InsightIQ versions prior to 5.1.1, update to version 5.1.1 or later.
For Dell Data Lakehouse versions prior to 1.2.0.0, update to version 1.2.0.0 or later.
Fix
Insecure Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Data Lakehouse
Dell Insightiq
Dell Powerflex Appliance
Dell Powerflex Custom Node
Dell Powerflex Rack
Powerflex Manager